# CVE-2026-49325

## Summary

- **CVE ID:** CVE-2026-49325
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-1384, CWE-754, CWE-693
- **Published:** May 29, 2026
- **Last Modified:** Jun 27, 2026

## Description

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with access to the Wireless Control Module (WCM) wiring harness to bypass the anti-theft shutdown. The WCM signals shutdown to a peer ECU via a falling-edge voltage transition on a dedicated wire pair. The receiving ECU does not distinguish between an active shutdown pulse and an open-circuit / disconnected condition; interrupting the relevant wires leaves the motorcycle fully operable even though the WCM never validated the rider's PIN. Specific connector details have been withheld pending vendor remediation.

## Affected Products

- Indian Motorcycle (Polaris Inc.) — Scout Bobber + Tech (2025)
- Indian Motorcycle — Scout Bobber + Tech (2025)

## References

- [CNA](https://cwe.mitre.org/data/definitions/1384.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._